vendor:
TwonkyMedia Server
by:
Sven Fassbender
6.1
CVSS
MEDIUM
Persistent XSS
79
CWE
Product Name: TwonkyMedia Server
Affected Version From: 7.0.11
Affected Version To: 8.5
Patch Exists: YES
Related CWE: CVE-2018-7203
CPE: a:lynx_technology:twonky_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2018
TwonkyMedia Server 7.0.11-8.5 Persistent XSS
TwonkyMedia Server 7.0.11-8.5 is vulnerable to persistent XSS. The vulnerability exists in the web UI of the TwonkyMedia Server. An attacker can inject malicious JavaScript code into the web UI of the TwonkyMedia Server. The malicious JavaScript code will be executed in the browser of the user who visits the web UI of the TwonkyMedia Server. The vulnerability can be exploited by sending a specially crafted HTTP request to the TwonkyMedia Server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of TwonkyMedia Server.